That's the key...
The key to this new malware is that it takes over the operating system at a very low-level (likely right above the kernel). This would give it control over what other applications can see; if the malware is below the level of the anti-malware, it can send fake information to it since it has "more control." So, it does not need to delete "hd files." Instead, it just spoofs them with the location Y data when querying for location X data as stated in the article.